NIST CSF RS.MI - Incident Mitigation
Contain cybersecurity incidents to prevent expansion and eradicate threats to mitigate their effects on the organization
Where this comes from
Provision: RS.MI - Incident Mitigation
Instrument: NIST Cybersecurity Framework 2.0 (February 2024)
Citation: NIST Cybersecurity Framework 2.0, February 26, 2024, Section RS.MI (Incident Mitigation), Sub-categories RS.MI-01 through RS.MI-02
Text version: CSF 2.0
Who it applies to
It applies when all of these are true:
- Data categories collected — any answer
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Runbooks exist to contain incidents and prevent their expansion
- Threats are eradicated from affected systems and verified as removed
- Containment and eradication actions are logged with timestamps and responsible parties
- Post-incident verification confirms the threat no longer persists
- System handles null/empty input gracefully (no 500 errors)
Questions people ask
- Does NIST CSF RS.MI - Incident Mitigation apply to my service?
- It applies when Data categories collected — any answer.
- From when does this apply?
- NIST CSF RS.MI - Incident Mitigation applies from 26 February 2024. Its current status is: in force.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.